| Requirement | Description |
| Patient’s understanding | This implies that patients have an exclusive right to know and understand how their sensitive and private health information are kept and utilized by any healthcare provider. |
| Patient’s control | This allows patients to be given permission to determine who can access his/her health data. |
| Confidentiality | Health information should be kept away from people who should not access it. The sanctity of the information should be maintained. |
| Data integrity | This ensures that manipulation and omission of health information is totally prohibited. Hence, health information being shared should be a true representation of original information without any form of amendment or alteration. |
| Consent exception | This stipulates that patient’s information could be accessed without his consent only in emergency cases. |
| Non-repudiation | Healthcare practitioner should deny the fact that it has performed a certain activity on the sensitive data of patient. Such activity should be supported with evidence to avoid dispute or suspicion. |
| Auditing | This is a requirement that health data should be well monitored frequently along with any form of activity to ensure that data is well secured and protected. This will assist user to know the confidential status of his data. |